false-positive-filter

A filter for static-analysis security findings that marks likely false alarms based on code patterns and surrounding context. Static analysis scans source code for possible security problems without running it.

In plain words
What is it for?
It helps filter likely false positives for XSS, SQL injection, CSRF, and findings in test code using patterns such as escaping, prepared statements, ORM protection, and CSRF middleware.
Why use it?
It reduces time spent reviewing findings that are probably not real vulnerabilities, while keeping lower-confidence findings for human review.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/morodomi/dev-crew/false-positive-filter
Clone the repo
git clone --depth 1 https://github.com/morodomi/dev-crew
Per session 27 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,067 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00027 $0.01067
Opus 5 $0.00014 $0.00534
Sonnet 5 $0.00005 $0.00213
Haiku 4.5 $0.00003 $0.00107

Measured yesterday against content hash d66b52904851, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

false-positive-filter scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/false-positive-filter.md · 98 lines

How it starts

The opening of the file, as written. The whole thing — 98 lines — stays where its author put it; the contents beside it link to each section on GitHub.

False Positive Filter

静的解析で検出された脆弱性の誤検知を自動的にフィルタリングするエージェント。

Filter Rules

Pattern-Based Filters

Category Pattern Action Confidence
Sanitized Output htmlspecialchars, e(), {{ }} Mark as FP (XSS) 0.95
Prepared Statement ->where(), DB::select() with ? Mark as FP (SQLi) 0.95
Test Code /tests/, /spec/, *Test.php Mark as FP (All) 1.00
Security Ignore @security-ignore (with required attrs) Mark as FP (All) 0.90

Note: /vendor/, /node_modules/ は除外対象外。sca-attackerで別途脆弱性検出。

Context-Based Filters

Category Context Check Action
Framework Auto-Escape Blade {{ }}, Jinja2 default Mark as FP (XSS)
ORM Protection Eloquent, Django ORM Mark as FP (SQLi)
CSRF Middleware VerifyCsrfToken enabled Mark as FP (CSRF)

Confidence Scoring

Score Meaning Action
0.95-1.00 Very High Auto-exclude (厳格な条件のみ)
0.80-0.94 High Flag for quick review
0.50-0.79 Medium Flag for manual review
0.00-0.49 Low Keep as vulnerability

Note: 自動除外は0.95以上に限定し、False Negative導入リスクを最小化。

Context Retrieval Protocol

作業開始前に十分なコンテキストを段階的に収集する(最大3サイクル)。

十分性評価

以下が全て把握できていれば十分:

  • 該当関数全体のコード把握
  • 呼び出し元関数と import/use 先の実装確認
  • フレームワークのグローバル設定(ミドルウェア、フィルタ)確認

リファイン手順

  1. 検出された脆弱性 + 該当ファイルを読む
  2. 上記チェックリストで十分性を評価
  3. 不足があれば追加検索(Grep/Read/Glob)で補完
  4. 最大3サイクル繰り返し、超過時は以下のフェイルセーフを適用

フェイルセーフ

3サイクル超過時: コンテキスト不足の脆弱性は除外せず検出を残す(FP > FN)。 不明点リストをレポートに「要手動確認」として記載する。

Workflow

  1. security-scan出力を受け取る
  2. 各脆弱性に対してフィルタルールを適用:
    • Pattern-Based: コード内のサニタイズパターンをチェック
    • Context-Based: フレームワーク保護をチェック
    • Path-Based: テストコードパスをチェック
    • Comment-Based: @security-ignoreコメントをチェック
  3. Confidence scoreを計算
  4. 0.95以上は自動除外、それ以外はフラグ付き
  5. 結果をJSON形式で出力

Reference

詳細: false-positive-filter-reference.md

Read the full file on GitHub · 98 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 98 lines · 27 tokens per session scan A d66b52904851

Subscribe to this mod's changes

false-positive-filter is an agent published in the GitHub repository morodomi/dev-crew (1 stars, last pushed 4d ago), licensed MIT. It adds 27 tokens to every session and 1,067 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.